account securityUpdated 11 August 2026

Getting into your account, and getting back in

An account that holds a balance and a verified identity is worth more to an attacker than a social media login. The protections that matter are unglamorous, and almost all of them have to be arranged before anything goes wrong.

A phone and notebook on a desk during an account verification step
Account recovery is easier to arrange before you need it.
  • A verified identityLicensed platforms must verify identity and age under the 2025 Act, so an account carries documents as well as a balance.
  • Money held for youLicensed platforms must hold user funds in segregated accounts and ensure refundability, which makes account control a financial question.
  • A limit configurationSelf-exclusion, time limits and deposit limits are mandatory features. Whoever controls the login can change them.
  • A complaint routeGrievance redressal is required of licensed platforms, and the Act establishes an appellate tribunal. Both need you to prove who you are.

What you are protecting

Why this account is a harder target to lose than most

Losing access to a gaming account is unlike losing access to an ordinary service in two respects. The first is that there is money on the other side of the login. The second, and less obvious, is that regaining access requires satisfying a platform that is under legal obligations about identity, which means the recovery process is deliberately not casual.

That second point cuts both ways. It is why account takeover is harder than on a service with no verification requirement, and it is also why recovery is slower. A platform that must verify identity and age under the 2025 Act cannot simply accept an email request to move access to a new address, because doing so would undermine the obligation.

The attack that actually happens

The common failure is not a sophisticated intrusion. It is credential reuse: a password used on a gaming account that was also used somewhere that suffered a breach, combined with the absence of a second factor. The attacker does not need to break the platform, only to try a known password against a known email address.

The second common failure is a recovery channel that is weaker than the account. If the account is protected by a strong password and a second factor, but the recovery route is an email address protected by a password from 2015, the real strength of the account is that email password.

This desk does not publish any operator's specific security features, session policies or recovery timelines. It has verified none of them. Ask the platform what it supports and hold it to the written answer.

A smartphone lying face up on a wooden desk displaying a blank rounded input panel beside a closed notebook
A second factor turns a stolen password from a complete failure into an inconvenience.

The one control worth the trouble

What a second factor does and does not stop

A second factor means access requires something beyond the password: a code from an authenticator application, a code sent to a registered device, or a hardware key. Its value is specific. It defeats the credential-reuse attack described above almost entirely, because knowing the password is no longer sufficient.

It does not defeat everything. A code entered into a convincing fake login page is a code the attacker now has, and codes sent by message can be intercepted if the phone number itself is compromised. An authenticator application is generally the stronger of the two common options, because the code is generated on the device rather than transmitted to it.

Whichever is available, generate and store the backup codes at the moment you enable it. A second factor with no recovery path is a lockout waiting for a lost phone, and recovering an account with a verified identity behind it is slower than most people expect.

Do it now

Setting up an account you can still reach in a year

Five steps, all of which are easier before there is a balance or a problem.

  1. Use a unique password

    The password on an account that holds money should exist nowhere else. Length matters more than symbol substitution, and a password manager removes the need to remember it.

    If you have reused a password here, change it before doing anything else on this list.

  2. Turn on a second factor and save the backup codes

    Enable whatever the platform offers, preferring an authenticator application over message-delivered codes where both exist. Write the backup codes down and store them away from your password manager.

    Codes stored in the same vault as the password protect you against nothing if that vault is what gets compromised.

  3. Secure the recovery channel

    The email address or phone number used for recovery is functionally part of the account. Give the email account its own unique password and its own second factor.

    An account is only as strong as the weakest route into it, and the recovery route is usually that route.

  4. Record your exact registered details

    Note the registered name spelling, the email address used and the date you opened the account. A recovery conversation with a platform that must verify identity under the Act will turn on details like these.

    Keep the note somewhere that does not depend on being logged in to read it.

  5. Check your limits at the same time

    While you are in the settings, set the deposit limit and time limit. Licensed platforms must provide self-exclusion, time limits and deposit limits under the Act, so the controls are there.

    Security and limits live in the same part of an account for a practical reason: both are decisions best made while nothing urgent is happening.

If you are locked out

Three routes back in, in order of likely success

Work through these in sequence. Each one asks more of you than the last.

A printed card of numbered backup codes resting on a desk beside a pen

What each route requires

01 · A backup code
The fastest route, and the reason to generate codes when enabling a second factor. It needs nothing from the platform's support team and no waiting.
02 · A password reset to a controlled address
Works when you still hold the registered email or phone. This is why securing the recovery channel matters as much as securing the account itself.
03 · Identity-based recovery through support
The slowest route, because the platform must satisfy its obligation to verify identity before moving access. Expect to supply the same documents used at verification, and expect the process to take time rather than minutes.
A printed account recovery form resting on a desk beside a pen
A session left open on a shared device hands over the limits as well as the balance.

The overlooked risk

Shared phones, saved sessions and the limit you set last week

Most discussion of account security concentrates on the password, which is the part an attacker at a distance has to defeat. The nearer risk is a session left signed in on a device someone else uses, because it bypasses the password entirely and grants everything the account holder has.

That includes the limits. Self-exclusion, time limits and deposit limits are mandatory features on licensed platforms under the 2025 Act, and they are configuration rather than law: whoever is signed in can raise or remove them. A person who has set a deposit limit as a genuine constraint on themselves has a specific reason to make sure a second person cannot reach that setting.

Sign out on any device you do not exclusively control, and check whether the platform lists active sessions so you can end ones you do not recognise. If you have set limits as a self-control measure, treat the login as part of that measure rather than as a separate concern.

Choosing a second factor

How the common options differ

If a platform offers more than one, this is the basis for choosing. If it offers only one, use it.

None of these protects against entering a code into a fake login page. Check the address bar before typing a code anywhere.

Second-factor options compared
MethodHow the code reaches youMain weakness
Authenticator applicationGenerated on your device, never transmittedLosing the device without backup codes saved
Code sent by messageSent to your registered numberExposed if the number itself is compromised or reassigned
Code sent by emailSent to your registered addressOnly as strong as the email account's own protection
Hardware keyHeld physically by youCost, and platform support is uncommon in this category

Reader questions

Access problems readers write in about

Short answers, with the limits of what this desk can tell you stated plainly.

I have lost my phone and my backup codes. What now?

You are on the identity-based recovery route, which means contacting the platform's support and expecting to prove who you are with the documents used at verification. A licensed platform cannot shortcut this, because verifying identity is an obligation the 2025 Act places on it.

Set expectations accordingly and keep a dated record of the correspondence. If recovery stalls unreasonably, licensed platforms must provide a grievance mechanism. The escalation page covers how to use it.

Should I let a browser save this password?

A dedicated password manager is preferable, because it keeps the credential behind its own authentication rather than behind whoever has the device unlocked. A browser store on a shared machine is effectively a shared password.

If a browser store is what you will actually use, it is better than reusing a memorable password across services.

The platform does not offer two-step verification. Is that a problem?

It is a genuine weakness, and worth weighing alongside the other checks on an operator. The 2025 Act requires identity and age verification and data protection of licensed platforms, but this desk is not going to characterise a specific security feature as legally mandated when it has not read that requirement in the Act.

Compensate with a long unique password and a well-protected recovery email, and apply the wider assessment method before committing funds.

Can someone else use my account if I am supervising?

No, and it puts your own access at risk. Licensed platforms must verify identity and age and must disallow access to minors, so an account used by someone other than the verified holder is a breach of the basis on which it was opened.

The consequence is not theoretical: it gives the platform a reason to freeze the account, and a withdrawal to a verified holder is exactly where that surfaces.

Does this desk know how long recovery takes at a given platform?

No. It has located no primary source for recovery timelines at any operator and will not estimate one.

Ask the platform for its stated process before you need it, and keep the answer with your account notes.

Do these three now

The account tasks worth ten minutes

All three are cheap today and expensive after a lockout or a takeover.

Read the verification guide

  • Is the password on this account used nowhere else, and is it stored in a manager rather than remembered?
  • Is a second factor enabled, with backup codes written down and stored away from the password?
  • Is the recovery email or phone number one you still control, and does it have its own protection?

Sources for the regulatory statements above

  • Promotion and Regulation of Online Gaming Act, 2025The obligation on licensed platforms to verify identity and age and to disallow access to minors; mandatory self-exclusion, time limits and deposit limits; segregated user funds and refundability; grievance redressal and data protection; the Online Gaming Appellate Tribunal.

No operator's security features, session policies or recovery timelines appear above, because this desk has verified none of them. Ask the platform directly and keep the written answer with your account notes.